Integrity and confidentiality are at the core of the the sixth data protection principle. In this article, we will embark on a journey to explore this principle in depth, comprehending its implications, and understanding how it shapes the landscape of data management.
Contents
What Does the GDPR Say?
Article 5(f) of the GDPR says that data shall be:
“processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).”
The Essence of Integrity and Confidentiality
The sixth data protection principle, often referred to as the “integrity and confidentiality” principle, is rooted in the GDPR. Its core aim is to guarantee the security and responsible handling of personal data. To unravel its significance, let’s break it down:
Deciphering Integrity
At its core, the principle of integrity ensures that personal data remains accurate and reliable. This entails taking measures to prevent unauthorised alterations, data corruption, and inaccuracies.
Accuracy and reliability are different from security, although the right security arrangements help. Remember, a data breach includes the accidental or deliberate alteration or corruption of personal data.
Safeguarding Confidentiality
Confidentiality is a cornerstone of data protection. This aspect of the principle ensures that personal data is accessible only by authorised individuals and protected from unauthorised disclosure.
Again, this goes further than security. Confidentiality can be breached by inappropriate internal data sharing or even people discussing personal information where they can be overheard.
Appropriate Security Arrangements
Information security means putting in place the right arrangements to prevent a personal data breach. As noted above this means preventing:
-
unauthorised access
-
inappropriate sharing
-
deletion or destruction
-
corruption or alteration
of data. How you prevent that depends on both the nature of the personal information that you have, and the resources available for information security. The greater the volume of personal information, the more sensitive information you have, or the vulnerabilities of the people whose information you collect or process will all influence the level of security required.
For both physical and electronic data there need to be appropriate access controls and barriers to data loss. You systems and devices should be able to record access by users and detect confidentiality breaches.
Overall the arrangements you put in place must be able to mitigate the risk of both a data breach and the consequences for people whose data are affected.
Technical and Organisational Measures
Technical and organisational measures is an important phrase. It means the GDPR expects you to go beyond physical and electronic security and think about people and organisational culture. You need the right kind of security policies, employee training, and other measures in place to help people do the right thing. You also need to ensure responsibility for information integrity and confidentiality is assigned to the right people including a Data Protection Officer.
Sign Up Here:
Understanding why the integrity and confidentiality principle is pivotal is integral to responsible data management. Every business will benefit from understanding and abiding by the sixth data protection principle. Data integrity is inseparable from trust. When personal data is maintained with integrity, it enhances trust in data-driven processes, decisions, and the organisations that use this data. This partly comes from the need to engage with people about their data to ensure it remains accurate and up to date, and is only used for specified purposes. Ensuring confidentiality is a crucial measure in mitigating data breach risks. By protecting data from unauthorised access, corruption or loss of data organisations reduce the probability of data breaches, safeguarding the privacy of individuals. This also reduces the risk of regulatory action, civil action, and negative publicity. The GDPR imposes specific obligations on data controllers and processors regarding the application of the integrity and confidentiality principle. They include: Implementing robust security measures is non-negotiable. Encryption, access controls, and cybersecurity practices are crucial to maintaining data integrity and confidentiality. Educating employees about data security and confidentiality is vital. A well-informed workforce is the first line of defense against data breaches. They will help prevent a data breach, but also help notify you quickly if anything goes wrong. You cannot know what appropriate technical and organisational measures looks like for your organisation if you do not understand what personal information you need to collect and process for your business activities. To uphold the principles of integrity and confidentiality, organisations must adopt best practices: Frequent data security audits and assessments help identify vulnerabilities and maintain data integrity and confidentiality. For example each year NHS organisations undertake a diagnostic assessment called the Data Security and Protection Toolkit that looks at everything from information security to training completion. Being prepared for data breaches is as crucial as preventing them. An incident response plan ensures swift and effective action if a breach occurs. Protection personal data and mitigating a personal data breach should be part of every organisation’s business continuity planning. Instilling a culture of ethical data handling within an organisation ensures that employees at all levels are committed to maintaining the integrity and confidentiality of personal data. Explore some of the wider concepts we have touched on in this article: Gain an understanding of sensitive personal data here Learn more about how to handle a data breach here Find out about the penalties for breaching GDPR here The sixth data protection principle, which emphasises integrity and confidentiality, plays an indispensable role in the GDPR’s framework. Upholding this principle is not only a legal requirement but a moral obligation to safeguard data accuracy, mitigate data breach risks, and maintain individuals’ trust in data processing. By adhering to security measures, educating employees, and adopting best practices, organisations can ensure that personal data remains secure, reliable, and confidential, thereby promoting responsible data management and protecting individuals’ rights. Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course. Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.
The Benefits of Ensuring Integrity and Confidentiality
Trust and Confidence
Reducing the Risk of a Data Breach
Summary: Your Obligations
Security Measures
Employee Training
Understanding your Data Processing Activities
Data Security Best Practices
Regular Audits and Assessments
Incident Response Plan
Ethical Data Handling
Further Reading
Conclusion: Emphasising the Significance of Integrity and Confidentiality
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: